Siemens RUGGEDCOM ROX II Code Injection Vulnerability in VRF Context Allowing Root Access

Vulnerability

A code injection vulnerability has been identified in the Siemens RUGGEDCOM ROX II family, affecting all versions prior to 2.17.0. The vulnerability arises when the device is using Virtual Routing and Forwarding (VRF), allowing an attacker to execute arbitrary code with root privileges.

Impact

Exploitation of this vulnerability allows for unauthorized code execution as the root user on the affected device.

Remediation

Users are advised to update to version 2.17.0 or later. Additional guidance can be found on the Siemens support website.

Added: Dec 9, 2025, 9:00 PM
Updated: Dec 9, 2025, 9:00 PM

Vulnerability Rating

Custom Algorithm
spread
2.6
impact
7.5
exploitability
4.4
remediation
7.7
relevance
1.4
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.